Goto

Collaborating Authors

 security operation center


A Unified Framework for Human AI Collaboration in Security Operations Centers with Trusted Autonomy

arXiv.org Artificial Intelligence

This article presents a structured framework for Human-AI collaboration in Security Operations Centers (SOCs), integrating AI autonomy, trust calibration, and Human-in-the-loop decision making. Existing frameworks in SOCs often focus narrowly on automation, lacking systematic structures to manage human oversight, trust calibration, and scalable autonomy with AI. Many assume static or binary autonomy settings, failing to account for the varied complexity, criticality, and risk across SOC tasks considering Humans and AI collaboration. To address these limitations, we propose a novel autonomy tiered framework grounded in five levels of AI autonomy from manual to fully autonomous, mapped to Human-in-the-Loop (HITL) roles and task-specific trust thresholds. This enables adaptive and explainable AI integration across core SOC functions, including monitoring, protection, threat detection, alert triage, and incident response. The proposed framework differentiates itself from previous research by creating formal connections between autonomy, trust, and HITL across various SOC levels, which allows for adaptive task distribution according to operational complexity and associated risks. The framework is exemplified through a simulated cyber range that features the cybersecurity AI-Avatar, a fine-tuned LLM-based SOC assistant. The AI-Avatar case study illustrates human-AI collaboration for SOC tasks, reducing alert fatigue, enhancing response coordination, and strategically calibrating trust. This research systematically presents both the theoretical and practical aspects and feasibility of designing next-generation cognitive SOCs that leverage AI not to replace but to enhance human decision-making.


Towards AI-Driven Human-Machine Co-Teaming for Adaptive and Agile Cyber Security Operation Centers

arXiv.org Artificial Intelligence

Security Operations Centers (SOCs) face growing challenges in managing cybersecurity threats due to an overwhelming volume of alerts, a shortage of skilled analysts, and poorly integrated tools. Human-AI collaboration offers a promising path to augment the capabilities of SOC analysts while reducing their cognitive overload. To this end, we introduce an AI-driven human-machine co-teaming paradigm that leverages large language models (LLMs) to enhance threat intelligence, alert triage, and incident response workflows. We present a vision in which LLM-based AI agents learn from human analysts the tacit knowledge embedded in SOC operations, enabling the AI agents to improve their performance on SOC tasks through this co-teaming. We invite SOCs to collaborate with us to further develop this process and uncover replicable patterns where human-AI co-teaming yields measurable improvements in SOC productivity.


AI-Driven Guided Response for Security Operation Centers with Microsoft Copilot for Security

arXiv.org Artificial Intelligence

Security operation centers contend with a constant stream of security incidents, ranging from straightforward to highly complex. To address this, we developed Copilot Guided Response (CGR), an industry-scale ML architecture that guides security analysts across three key tasks -- (1) investigation, providing essential historical context by identifying similar incidents; (2) triaging to ascertain the nature of the incident -- whether it is a true positive, false positive, or benign positive; and (3) remediation, recommending tailored containment actions. CGR is integrated into the Microsoft Defender XDR product and deployed worldwide, generating millions of recommendations across thousands of customers. Our extensive evaluation, incorporating internal evaluation, collaboration with security experts, and customer feedback, demonstrates that CGR delivers high-quality recommendations across all three tasks. We provide a comprehensive overview of the CGR architecture, setting a precedent as the first cybersecurity company to openly discuss these capabilities in such depth. Additionally, we GUIDE, the largest public collection of real-world security incidents, spanning 13M evidences across 1M annotated incidents. By enabling researchers and practitioners to conduct research on real-world data, GUIDE advances the state of cybersecurity and supports the development of next-generation machine learning systems.


How AI is used in Security Operation Centers (SOC)

#artificialintelligence

Artificial intelligence and machine learning are tools that can assist cybersecurity teams in reducing breach risk. Here's an overview of how it works Artificial Intelligence (AI) is software that reacts to its environment. Machine Learning (ML) is a type of computing that learns and adapts without explicit instructions, using statistical models and algorithms. AI uses the outcomes from ML to react. In a Security Operations Center (SOC) setting, AI can enhance security.


5 Signs You Should Re-Evaluate Your Relationship with Your MSSP

#artificialintelligence

From Equifax to Yahoo, and Facebook to Marriott, large-scale data breaches impacting hundreds of millions of consumers have received their fair share of media attention in recent years. All this ink hasn't been spilled (or pixels displayed) in vain: there's growing awareness among business leaders of the security and privacy risks their organizations face, and increasing concern that their preparedness may be inadequate. In a recent PwC survey, for example, 72% of CEOs worldwide listed cybercriminal activity as a significant threat to their businesses, yet only 35% were comfortable with their organization's digital resilience and readiness to face such threats. Especially among small and mid-sized enterprises, the growth in awareness of the severity and urgency of cybersecurity risks is driving demand for managed security services. Organizations are increasingly turning to external vendors to help them build, maintain, and monitor their security operations programs and the technologies that comprise them.


4 Ways to Integrate Cyber Security Automation Within Your Enterprise - Hashed Out by The SSL Store

#artificialintelligence

Businesses of all sizes continually seek ways to increase efficiency and profitability in all areas of their organization -- everything from general operations to cyber security. Regardless of how you feel about automation on a personal level -- whether you think automation is great or it's the harbinger of death for cyber security jobs -- it doesn't change the fact that automation is poised to change the very nature of cyber security jobs in the future. That's because one of the best ways to accomplish many of the goals business have is to integrate process automation and cyber security automation into their operations. Business automation comes in many forms, though, and can include a variety of process automation and security automation tools. So, what are these tools, how do they work, and how can they be integrated into your security processes?


Detecting random filenames using (un)supervised machine learning

#artificialintelligence

Combining both n-grams and random forest models to detect malicious activity. An essential part of Managed Detection and Response at Fox-IT is the Security Operations Center. This is our frontline for detecting and analyzing possible threats. Our Security Operations Center brings together the best in human and machine analysis and we continually strive to improve both. For instance, we develop machine learning techniques for detecting malicious content such as DGA domains or unusual SMB traffic.


The Rise of Next Generation Security Operation Center (NG-SOC)

#artificialintelligence

The year 2017 has been dominated by the worst cyber-attacks and high profile data breaches. Consumer credit score company Equifax has revealed that hackers accessed up to 143 million customer account details earlier this year. The data breach happened on July 29 and the details taken include names, social security numbers, drivers' licenses, and credit card numbers of around 200,000 people This breach might have cost multimillion dollar as penalties but the cost they will pay for the most important element of business is client trust and reputation, which they might have built over years. The incidents like this have made organizations realized that the threat landscape is changing faster, new challenges are emerging every day. Organisations have to change their defense strategy from basic level majors and ad hoc response to more sophisticated and robust processes.


DARKMENTION: A Deployed System to Predict Enterprise-Targeted External Cyberattacks

arXiv.org Artificial Intelligence

Recent incidents of data breaches call for organizations to proactively identify cyber attacks on their systems. Darkweb/Deepweb (D2web) forums and marketplaces provide environments where hackers anonymously discuss existing vulnerabilities and commercialize malicious software to exploit those vulnerabilities. These platforms offer security practitioners a threat intelligence environment that allows to mine for patterns related to organization-targeted cyber attacks. In this paper, we describe a system (called DARKMENTION) that learns association rules correlating indicators of attacks from D2web to real-world cyber incidents. Using the learned rules, DARKMENTION generates and submits warnings to a Security Operations Center (SOC) prior to attacks. Our goal was to design a system that automatically generates enterprise-targeted warnings that are timely, actionable, accurate, and transparent. We show that DARKMENTION meets our goal. In particular, we show that it outperforms baseline systems that attempt to generate warnings of cyber attacks related to two enterprises with an average increase in F1 score of about 45% and 57%. Additionally, DARKMENTION was deployed as part of a larger system that is built under a contract with the IARPA Cyber-attack Automated Unconventional Sensor Environment (CAUSE) program. It is actively producing warnings that precede attacks by an average of 3 days.


It's Time to Adopt AI in Your Security Operations Center

#artificialintelligence

Security analysts: We know you're overworked, understaffed and overwhelmed, and we understand that it's not your fault. It's not humanly possible for you to keep up with the ever-expanding threat landscape, especially given how busy you are with the day-to-day tasks of running your security operations center (SOC). We want you to know you're not alone. According to research performed by the Enterprise Strategy Group, almost 51 percent of organizations in 2018 reported a "problematic shortage" of cybersecurity skills. Cybersecurity job fatigue is real, and according to ESG, almost 38 percent of security professionals claimed that the skills shortage has led to burnout and staff attrition.